diff options
author | Tom Fitzhenry <tom@tom-fitzhenry.me.uk> | 2024-05-16 22:09:13 +1000 |
---|---|---|
committer | tomf <tom@tom-fitzhenry.me.uk> | 2024-06-11 19:28:32 +1000 |
commit | 725777250b7d55d3069abf09f25cb489eb634c7d (patch) | |
tree | d330f93a0ba8072f298556942d09452aa8f6afe0 /nixos/tests/all-tests.nix | |
parent | 8c931d0ab0d918797e0133988403ac2a2a8e6443 (diff) |
nixos/shadow: introduce security.shadow.enable
Allow users to disable the shadow authentication suite. My primary motivation is to reduce the attack surface via setuid binaries, which shadow understandably introduces many. I realised, however, that I don't use any of these. The test demonstrates login working without needing the shadow suite.
Diffstat (limited to 'nixos/tests/all-tests.nix')
-rw-r--r-- | nixos/tests/all-tests.nix | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 7529195262a64..92238016af569 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -380,6 +380,7 @@ in { grafana-agent = handleTest ./grafana-agent.nix {}; graphite = handleTest ./graphite.nix {}; graylog = handleTest ./graylog.nix {}; + greetd-no-shadow = handleTest ./greetd-no-shadow.nix {}; grocy = handleTest ./grocy.nix {}; grow-partition = runTest ./grow-partition.nix; grub = handleTest ./grub.nix {}; |